Skip to content
KitploitKITPLOIT
OutilsBlog
Soumettre
OutilsBlog
Soumettre

Outils de Hacking, PenTest et Cybersécurité pour votre Arsenal de Sécurité !

Kitploit est un répertoire d'outils de hacking, de cybersécurité et de pentesting. Découvrez les dernières mises à jour des projets pour trouver des vulnérabilités, analyser des systèmes, automatiser les tests et renforcer votre sécurité.

··Flux·Contact·Confidentialité·© 2026 Kitploit

Répertoire d'outils

Catégories

Voir toutes les catégories
Loading categories
Evilginx-Phishing-Infra-Setup — Guide de configuration de l'infrastructure de phishing Evilginx - Sécurisation de l'infrastructure Evilginx et Gophish, Suppression des IOCs, TTPs de phishing | Kitploit
Outils/GitHubGitHub/an0nud4y/evilginx-phishing-infra-setup
Outils de PhishingÉvasion IDS/IPSHameçonnageCommandement et ContrôleIngénierie SocialeApprentissage et ÉducationRed TeamingRessources OrganiséesSécurité des Emails

Populaires

Voir tout →

Découvrez les outils les plus utilisés par notre communauté.

Explorer tous les outils

Parcourez notre collection d'outils

Voir tous les outils →
Partager
GitHuban0nud4y/evilginx-phishing-infra-setup

Evilginx-Phishing-Infra-Setup

Guide de configuration de l'infrastructure de phishing Evilginx - Sécurisation de l'infrastructure Evilginx et Gophish, Suppression des IOCs, TTPs de phishing

Voir le dépôt
598115il y a 1 anVérifié par Kitploit

Guide de mise en place d'infrastructure pour des engagements de phishing

Note : Ceci est une copie de mes notes personnelles. Veuillez ne pas vous y fier entièrement.

Table des matières

  • Blogs/Talks
  • Automatisation de l'infrastructure Red Team/Phishing
  • Achat de domaine et techniques de catégorisation
  • Améliorer la rédaction d'e-mails de phishing à l'aide d'outils
  • Tester le caractère spam d'un e-mail
  • Simuler des e-mails de phishing / Phishing Purple Team
  • Awesome Enterprise Email Security
  • Délivrer des e-mails dans la boîte de réception
  • Engagements de phishing avec Evilginx
    • Construire des phishlets Evilginx
    • Scripts d'installation d'Evilginx
    • Conseils pour sécuriser l'infra Evilginx
    • Blogs/Talks de recherche sur Evilginx
    • Tactiques de défense contre Evilginx
  • Sécurisation de l'infra GoPhish
    • Blogs/Talks de recherche sur GoPhish
    • Alternatives à GoPhish
  • Post-exploitation AiTM / Blogs/Talks de recherche sur le phishing
  • Autres techniques/Blogs/Recherches
  • Talks de recherche sur le phishing

Blogs/Talks

  • BHIS | How to Build a Phishing Engagement - Coding TTP's : https://m.youtube.com/watch?si=YTjMa8XBusj_tPdc&v=VglCgoIjztE&feature=youtu.be

Automatisation de l'infrastructure Red Team/Phishing

  • https://github.com/dazzyddos/HSC24RedTeamInfra/blob/main/RedTeamInfraAutomation.pdf
  • OFFENSIVEX 2024 - Vincent Yiu - Red Team Tips in 2024 : https://youtu.be/ECIBCbMfeo4?feature=shared
  • https://github.com/bluscreenofjeff/Red-Team-Infrastructure-Wiki
  • Déployer une infrastructure de phishing à la volée : https://github.com/VirtualSamuraii/flyphish
  • https://labs.jumpsec.com/putting-the-c2-in-c2loudflare/

Achat de domaine et techniques de catégorisation

  • Vérifier les domaines expirés et éventuellement acheter les bons

    • https://expireddomains.net/
  • Catégorisation de domaine

    • Bluecoat/Symantec - https://sitereview.bluecoat.com/#/
    • McAfee - https://www.trustedsource.org
    • Palo Alto Wildfire - https://urlfiltering.paloaltonetworks.com
    • Websense - https://csi.forcepoint.com & https://www.websense.com/content/SiteLookup.aspx (nécessite inscription)
    • FortiGuard - https://www.fortiguard.com/webfilter
    • IBM X-force - https://exchange.xforce.ibmcloud.com
    • Cyren - https://www.cyren.com/security-center/url-category-check-gate
    • Checkpoint - https://www.checkpoint.com/urlcat/main.htm (nécessite inscription)
    • Trend Micro - https://global.sitesafety.trendmicro.com/
    • Sophos - https://secure2.sophos.com/en-us/support/contact-support.aspx (soumission uniquement ; pas de vérification) (Cliquez sur Submit a Sample -> Web Address)
    • BrightCloud - http://www.brightcloud.com/tools/url-ip-lookup.php
    • LightSpeed Systems - https://archive.lightspeedsystems.com/
  • Automatisation de la vérification/soumission de réputation de domaine

    • Domainhunter: https://github.com/threatexpress/domainhunter
    • Chameleon : https://github.com/mdsecactivebreach/Chameleon

Améliorer la rédaction d'e-mails de phishing à l'aide d'outils

  • mgeeky : https://github.com/mgeeky/Penetration-Testing-Tools/tree/master/phishing
  • HTML-Linter (éviter les mots courants des e-mails de phishing) : https://github.com/mgeeky/Penetration-Testing-Tools/blob/master/phishing/phishing-HTML-linter.py
  • Decode-Spam-Headers : https://github.com/mgeeky/decode-spam-headers

Tester le caractère spam d'un e-mail

  • https://www.mail-tester.com/

Simuler des e-mails de phishing / Phishing Purple Team

  • https://delivr.to/

Awesome Enterprise Email Security

  • https://github.com/0xAnalyst/awesome-email-security
  • Gartner Magic Quadrant for Email Security Platforms email-security-providers

Délivrer des e-mails dans la boîte de réception

  • Méthode 1 : Utilisation de fournisseurs de services de messagerie

    • Utiliser SendGrid - http://sendgrid.com/
      • Service utile mais honnêtement, il faut le plan Pro pour avoir de la chance de ne pas être sur une liste de spam
    • MailGun - https://app.mailgun.com/
      • Je n'ai eu aucun problème
    • Amazon AWS SES
    • Brevo : https://www.brevo.com/free-smtp-server/
    • Outlook
    • Gmail
    • Configurer un locataire Azure pour obtenir un domaine onmicrosoft.com comme attackdomain.onmicrosoft.com qui peut être utilisé à la fois pour l'envoi d'e-mails et le phishing en tant que domaine
    • LarkSuite (autorise les domaines personnalisés) : https://www.larksuite.com/
    • Zoho (Utiliser l'option e-mail "Gratuit à vie" de Zoho) : https://www.zoho.com/mail/custom-domain-email.html
    • Yandex : https://360.yandex.com/business/domain-mail/
  • Méthode 2 : Techniques diverses

    • Technique 1 : Par Andre Rosario - Depuis le Discord BreakDev Red

      • Si vous avez des problèmes de délivrabilité des e-mails à cause du filtrage, envisagez d'utiliser Microsoft 365 et Azure IPP pour envoyer des e-mails chiffrés à vos cibles !
        • Les e-mails proviennent de serveurs SMTP légitimes de Microsoft, ils ne peuvent donc pas être bloqués.
        • Les cibles qui reçoivent l'e-mail chiffré sont les seules à pouvoir l'ouvrir ; si elles le transfèrent à leur équipe DFIR, elles devront se connecter en tant que cet utilisateur pour voir votre message.
        • Orchestration facile dans le portail d'administration Microsoft de domaines personnalisés, créez un grand nombre de faux comptes.
        • M365 permet de définir des noms d'affichage arbitraires. Ainsi, dans Outlook d'une cible, l'e-mail peut sembler provenir de [email protected] mais en réalité il provient de (Les techniciens peuvent facilement le découvrir cependant)

Engagements de phishing avec Evilginx

  • Construire des phishlets Evilginx

    • Evilginx Mastery Course : https://academy.breakdev.org/evilginx-mastery
    • Documentation Evilginx : https://help.evilginx.com/
    • Collections de phishlets Evilginx : https://github.com/An0nUD4Y/Evilginx2-Phishlets
    • Techniques méconnues d'Evilginx : https://github.com/An0nUD4Y/Evilginx2-Phishlets?tab=readme-ov-file#some-less-known-techniques
  • Scripts d'installation d'Evilginx

    • https://gist.github.com/dunderhay/d5fcded54cc88a1b7e12599839b6badb
  • Conseils pour sécuriser l'infra Evilginx -

    • https://github.com/An0nUD4Y/Evilginx2-Phishlets#securing-evilginx-infra-tips

      root@kitploit:~
      - Rewrite URLs on Phishing Pages to avoid detection through URL Path pattern matching (by Kuba).
      - Remove IOCs (X-Evilginx header and Default Cert Details)
      - Modify Unauth redirect static contents
      - Modify code to request wildcard certificates for root domain from Let'sEncrypt other than requesting for each subdomains (As mentioned in Kuba's blog) - Check this repo for reference https://github.com/ss23/evilginx2
      - Put evilginx behind a proxy to help against TLS fingerprinting (JA3 and JA3S)
      - Use cloudflare in between if possible/feasible (You have to configure the SSL Settings correctly, change it to Full in cloudflare settings)
      - Use some known ASN blacklist to avoid getting detected like here (https://github.com/aalex954/evilginx2-TTPs#ip-blacklist)
      - Reduce the Number of proxyhosts in phishlet if possible to reduce content loading time.
      - Host Evilginx at Azure and use their domain (limit proxy host in phishlet to 1 or find a way , may be create multiple azure sub domains and try with that)
      - Add some sub_filters to modify the content of the pages to avoid content based detections, like (Favicon, form title font or style, or anything which seems relevant)
      - Block the feedback/telemetry/logs/analytics subdomains using the phishlet sub_filters which can log the domain or may help later on analysis.
      - See if js-injected is static or dynamic , if static modify the evilginx js-inject code to create dynamic/obfuscated version of your js for each user/target.
      - Make sure to not leak your Evilginx infra IP, Check the DNS history to make sure its not stored anywhere (Analysts may look for older DNS Records of the domain)
      - Be aware of this research : https://catching-transparent-phish.github.io/catching_transparent_phish.pdf , repo - https://catching-transparent-phish.github.io/
      

Blogs/Talks de recherche Evilginx :

  • Une mer calme n'a jamais fait un pêcheur expérimenté - Kuba Gretzky (x33fc0n 2024) :
    • Conférence : https://youtu.be/Nh99d3YnpI4?si=Ltwus2PS0z97gf2R
    • Diapositives : https://github.com/kgretzky/talks/blob/main/2024/x33fcon/a-smooth-sea-never-made-a-skilled-phisherman.pdf
  • La triforce de l'accès initial : https://trustedsec.com/blog/the-triforce-of-initial-access
    • Bobber : https://github.com/Flangvik/Bobber
  • Contournement de la détection Canary AiTM : https://insights.spotit.be/2024/06/03/clipping-the-canarys-wings-bypassing-aitm-phishing-detections/
  • Protéger Evilginx avec Cloudflare et obfuscation HTML : https://www.jackphilipbutton.com/post/how-to-protect-evilginx-using-cloudflare-and-html-obfuscation
  • (Améliorer la confiance de livraison des e-mails Evilginx) Ajouter les enregistrements SPF, DMARC, DKIM, MX : https://fortbridge.co.uk/research/add-spf-dmarc-dkim-mx-records-evilginx/
    • https://m3rcer.netlify.app/redteaming/spamfilterbypass/
  • Tactiques de phishing et OPSEC : https://mgeeky.tech/uploads/WarCon22 - Modern Initial Access and Evasion Tactics.pdf
  • Evilginx + BITB + Tactiques d'évasion : https://youtu.be/p1opa2wnRvg
  • Hook, Line and Phishlet - Conquérir AD FS avec Evilginx : https://research.aurainfosec.io/pentest/hook-line-and-phishlet/
  • Infrastructure de phishing O365 - https://badoption.eu/blog/2023/12/03/PhishingInfra.html
  • You Can’t See Me – Protéger votre infrastructure de phishing :

Tactiques de défense contre Evilginx

  • Démêler et contrer le phishing adversaire au milieu - X33fcon 2024 - https://youtu.be/-W-LxcbUxI4
  • Utiliser des HoneyTokens pour détecter AiTM : https://zolder.io/using-honeytokens-to-detect-aitm-phishing-attacks-on-your-microsoft-365-tenant/
  • Protéger contre le phishing moderne : https://bleekseeks.com/blog/how-to-protect-against-modern-phishing-attacks
  • https://www.youtube.com/watch?v=wTLB0Yh70_0
  • Détection d'evilginx via l'empreinte JA3, JA3S, JA4
    • Base de données JA4 : https://ja4db.com/

Sécurisation de l'infrastructure GoPhish

Ces modifications fonctionneront également avec la dernière version d'evilginx + gophish, à savoir evilginx3.3

  • Astuce : Utilisez le paramètre {{.URL}} dans le modèle de phishing lors de l'utilisation avec evilginx ( https://github.com/kgretzky/evilginx2/issues/1042#issuecomment-2052073864)

  • Modifications dans le code source de gophish et la structure des fichiers pour sécuriser l'infrastructure GoPhish

    • Supprimer les instances X-Gophish ( X-Gophish-Contact , X-Gophish-Signature)

    • Supprimer const ServerName= "gophish" et le remplacer par const ServerName= "IGNORE" dans le fichier config/config.go

    • Modifier le port par défaut du serveur Admin dans le fichier config.json.

    • Modifier les signatures des messages de test d'e-mail pour éviter la détection lors des tests SMTP. Controllers > api > util.go

      root@kitploit:~
      Controllers > api > util.go
      models > testdata > email_request.go
      models > testdata > email_request_test.go
      models > testdata > maillog.go
      models > testdata > maillog_test.go
      models > testdata > smtp_test.go
      

Blogs/Talks de recherche sur la post-exploitation/Phishing AiTM

  • AiTM (Post-Exploitation) : https://www.youtube.com/live/WY4mH-8TbWY?si=LkZ1LuduDln1vRuj
    • https://youtu.be/py68OE4tQ4Q?si=n6QlNuro88c1PRzn
  • https://trustedsec.com/blog/the-triforce-of-initial-access
  • https://www.youtube.com/live/tOzURCc-qUc?si=DMkLwXHVQomRMEJD## Autres Techniques/Blogs/Recherches
  • Pour abuser des sites légitimes pour le phishing : https://lots-project.com/
  • Muraena : https://github.com/muraenateam/muraena
  • NecroBrowser : https://github.com/muraenateam/necrobrowser
  • BITB : https://mrd0x.com/browser-in-the-browser-phishing-attack/
    • Frameless-bitb : https://github.com/waelmas/frameless-bitb
      • https://youtu.be/luJjxpEwVHI?si=sk8kMfdfhZbTz8qR
    • CuddlePhish : https://github.com/fkasler/cuddlephish
    • https://pushsecurity.com/blog/phishing-2-0-how-phishing-toolkits-are-evolving-with-aitm/
    • Okta chaîné avec Azure avec abonnement MFA automatique pour Okta et contournement de Frame Buster pour effectuer BITB : https://x.com/otterhacker/status/1929487165458641045?s=46&t=mlJvZy0Zrkrxzuvtt7m2cQ
      • https://github.com/OtterHacker/OktaGinx/
  • Phishing par Progressive Web Apps (PWA) : https://mrd0x.com/progressive-web-apps-pwa-phishing/
  • Phishing noVNC :

Conférences de recherche sur le phishing

  • https://youtu.be/zmo_tPbCXtA?si=4imjZtwQ6I9iu_tP
Télécharger l’outil
  • Blogs

    • https://medium.com/@frsfaisall/mastering-modern-red-teaming-infrastructure-leveraging-old-domains-for-reputation-based-bypasses-1fd8cc1768f7
  • [email protected]
  • Les e-mails proviennent d'IP et de domaines Microsoft légitimes, vous n'avez donc pas à vous soucier de la catégorisation du domaine ou de sa durée de vie, car c'est Microsoft.
  • Technique 2 : Utilisation de la fonctionnalité Azure External Invite - Depuis le Discord BreakDev Red

    • Azure External Invite peut être utilisé pour envoyer un e-mail avec un lien de redirection vers une URL de phishing
    • Les e-mails en masse peuvent également être envoyés, pour référence, consultez : https://learn.microsoft.com/en-us/entra/external-id/tutorial-bulk-invite
  • Conseils divers pour aider à faire atterrir les e-mails dans la boîte de réception.

    • Avoir un domaine avec une bonne réputation, vérifier la catégorisation du domaine
    • Avoir un domaine de plus d'un an ou utiliser un domaine expiré
    • Avoir des enregistrements DKIM, DMARC et SPF valides.
      • Mailgoose (vérifier si leur configuration SPF, DMARC et DKIM est correcte) : https://github.com/CERT-Polska/mailgoose
    • Ajouter un lien de désabonnement dans l'e-mail
    • Envoyer d'abord des e-mails bénins (peut aider pour la réputation)
    • Avoir un lien dans l'e-mail avec le même domaine que celui utilisé pour envoyer l'e-mail.
  • Blogs/Talks/Références

    • Outlook_Email_Auth_Bypass : https://gitlab.com/hxxpxxp/outlook_email_auth_bypass (Dans l'application de bureau et web Outlook, le "nom d'affichage" de l'en-tête "De" de l'e-mail peut manipuler l'adresse e-mail affichée à l'utilisateur, ce qui peut donner des e-mails de phishing plus convaincants)
    • Spy Pixel - Pixel d'image pour suivre les e-mails : https://github.com/collinsmc23/spy-pixel
    • EchoSpoofing : https://labs.guard.io/echospoofing-a-massive-phishing-campaign-exploiting-proofpoints-email-protection-to-dispatch-3dd6b5417db6
    • Blackhat USA 2024 - Novel Email Spoofing Attack Patterns : https://github.com/onhexgroup/Conferences/blob/main/Black Hat USA 2024 slides/Hao Wang %26 Caleb Sargent %26 Harrison Pomeroy %26 Renana Friedlich_Into the Inbox Novel Email Spoofing Attack Patterns.pdf
  • Remove X-Evilginx header (Check all the code lines with req.Header.Set and comment relevant functions in core/http_proxy.go file)

    root@kitploit:~
      // comment line 469
      req.Header.Set(p.getHomeDir(), o_host)
      
      //comment line 659
      req.Header.Set(p.getHomeDir(), o_host)
      
      // comment function at line 1791-1793
      func (p *HttpProxy) getHomeDir() string {
      	return strings.Replace(HOME_DIR, ".e", "X-E", 1)
      }
      
      // comment line 52-54
      const (
      	HOME_DIR = ".evilginx"
      )
    
  • To Modify Unauth redirect static contents, Search for <html> in core/http_proxy.go file and modify the html code to remove any static signatures.

  • Also to avoid the static injected js code signature detection , You can modify the code as below

    • Make sure to add "github.com/tdewolff/minify/js" in imports

      root@kitploit:~
      	re := regexp.MustCompile(`(?i)(<\s*/body\s*>)`)
      	var d_inject string
      
      	if script != "" {
      		minifier := minify.New() // "github.com/tdewolff/minify/js"
      		minifier.AddFunc("text/javascript", js.Minify)
      		obfuscatedScript, err := minifier.String("text/javascript", script)
      		if err != nil {
      			// Handle error - Obfuscation failed
      			d_inject = "<script" + js_nonce + ">" + "function doNothing() {var x =0};" + script + "</script>\n${1}"
      		}
      		d_inject = "<script" + js_nonce + ">" + "function doNothing() {var x =0};" + obfuscatedScript + "</script>\n${1}"
      		//d_inject = "<script" + js_nonce + ">" + "function doNothing() {var x =0};" + script + "</script>\n${1}"
      
      	} else if src_url != "" {
      		d_inject = "<script" + js_nonce + " type=\"application/javascript\" src=\"" + src_url + "\"></script>\n${1}"
      	} else {
      		return body
      	} 
      
  • Modify core/cert.db file as well

  • Change “rid” for gophish.

  • Use nginx , caddy or other proxies infront of evilginx.

  • Use Redirectors

    • Use cloudflare turnstile as evilginx redirector and block bots.
      • https://github.com/kgretzky/evilginx2/blob/master/redirectors/turnstile/index.html
    • Obfuscate html/js based redirectors
      • Suspicious HTTP User agents list : https://github.com/mthcht/awesome-lists/blob/main/Lists/suspicious_http_user_agents_list.csv
      • https://github.com/DosX-dev/WebSafeCompiler
    • Bot detection methods used by gabagool phishing kit : https://medium.com/@traclabs_/aitm-phishing-hold-the-gabagool-analyzing-the-gabagool-phishing-kit-531f5bbaf0e4
    • Meta html tag for redirection
      • <meta http-equiv="refresh" content="5;url=https://example.com">
  • Change default lure url pattern which is random string of length 8.

    root@kitploit:~
       // Line 728 in core/terminal.go file
      		l := &Lure{
      			Path:     "/" + GenRandomString(8),
      			Phishlet: args[1],
      		}
    
  • Rewrite URLs on Phishing Pages to avoid detection through URL Path pattern matching (by Kuba). [This Feature not available in evilginx Public Version, You have to implement it yourself.]

    root@kitploit:~
    # Only Work in Evilginx Pro Version
    # Similar functionality can be implemented in public version as well.
    rewrite_urls:
    
    trigger:
    domains: ['www.linkedin.com']
    paths: ['^/login$']
    rewrite:
    path: '/this/is/not/the/path/you/are/looking/for.php'
    query:
    
        {key:'a', value: 'HOW'}
        {key:'b', value: 'MUCH'}
        {key:'d', value: 'IS'}
        {key:'e', value: 'THE'}
        {key:'f', value: 'PHISH'}
        {key:'q', value: '{id}'}
    
    

    Untitled

  • Modify the lure/session identifier cookies signatured pattern and value (by @rad9800 )

    • Rule 1: Cookie name=XXXX-XXXX & value=64_hex_chars - https://gist.github.com/rad9800/bb73de360fc07ac544f0bc9faac9082d#file-index-js-L130
      • Responsible evilginx Code Functionality (For cookie-Name) : https://github.com/kgretzky/evilginx2/blob/9e32484719681892945130187ea52737b3d72051/core/http_proxy.go#L1984
      • Responsible evilginx Code Functionality (For cookie-Value) : https://github.com/kgretzky/evilginx2/blob/9e32484719681892945130187ea52737b3d72051/core/http_proxy.go#L895
    • Rule 2: Script path=/s/64_hex_chars.js with content-length=0
    • Rule 3: Both Rule 1 & Rule 2 present
      • the full snippet js blob logic is here https://gist.github.com/rad9800/bb73de360fc07ac544f0bc9faac9082d
  • Block Referrer headers from leaking your phishing domain name - check this research blog for reference :

    • Add below line in http_proxy.go file here (Chrome don’t respect this and when request is initiated by url() CSS function - check blog for more)
      • resp.Header.Set("Referrer-Policy", "no-referrer")
      • To automate from phishlet Check this PR : https://github.com/kgretzky/evilginx2/pull/1006
  • Define your own CSP (Content security Policy) to avoid telemetry/canary/detection by leaking phishing domain.

    • Read this for more : https://insights.spotit.be/2024/06/03/clipping-the-canarys-wings-bypassing-aitm-phishing-detections/
  • Check if target site is using some sort of canary tokens (CSS, JS) and avoid them

    • Bypassing (CSS,JS) Canary AiTM Detection : https://insights.spotit.be/2024/06/03/clipping-the-canarys-wings-bypassing-aitm-phishing-detections/
    • https://blog.thinkst.com/2024/01/defending-against-the-attack-of-the-cloned-websites.html
  • JA4 fingerprint evasion

    • https://github.com/refraction-networking/utls
    • https://github.com/juzeon/spoofed-round-tripper
  • BITB + evilginx + Frame Busting Bypass

    • https://x.com/otterhacker/status/1929487165458641045?s=46&t=mlJvZy0Zrkrxzuvtt7m2cQ
      • OktaGinx : https://github.com/OtterHacker/OktaGinx/blob/main/okta.yaml#L17
    • https://github.com/waelmas/frameless-bitb
    • Frame Busting Bypass Example Subfilter from : https://github.com/OtterHacker/OktaGinx/blob/44fed02954b6cd65e17ab581209a4d0f3b734c24/okta.yaml#L124 and https://github.com/OtterHacker/OktaGinx/blob/44fed02954b6cd65e17ab581209a4d0f3b734c24/okta.yaml#L82
      root@kitploit:~
      - triggers_on: 'login.microsoftonline.com'
      orig_sub: ''
      domain: 'okta.com'
      search: 'if\(e.self===e.top\){'
      replace: 'if(true){window.oldself=e.self;e.self=e.top;'
      mimes: ['text/html', 'charset=utf-8']- triggers_on: 'login.microsoftonline.com'
      orig_sub: ''
      domain: 'okta.com'
      search: 'X-Frame-Options: DENY'
      replace: 'Test: test'
      mimes: ['text/html', 'charset=utf-8']
      
      • Techniques de busting de cadre généralement utilisées
        • https://en.wikipedia.org/wiki/Framekiller
        • https://seclab.stanford.edu/websec/framebusting/framebust.pdf
          • Techniques courantes pour détecter la présence d'iframe
            root@kitploit:~
              if (top != self)
              if (top.location != self.location)
              if (top.location != location)
              if (parent.frames.length > 0)
              if (window != top)
              if (window.top !== window.self)
              if (window.self != window.top)
              if (parent && parent != window)
              if (parent && parent.frames && parent.frames.length>0)
              if((self.parent&&!(self.parent===self))&&(self.parent.frames.length!=0))
            
          • Les sites web peuvent utiliser la méthode suivante une fois l'iframe détecté pour effectuer une redirection
            root@kitploit:~
            top.location.replace(self.location)
             top.location.href = window.location.href
             top.location.replace(document.location)
             top.location.href = window.location.href
             top.location.href = "URL"
             document.write(’’)
             top.location = location
             top.location.replace(document.location)
             top.location.replace(’URL’)
             top.location.href = document.location
             top.location.replace(window.location.href)
             top.location.href = location.href
             self.parent.location = document.location
             parent.location.href = self.document.location
             top.location.href = self.location
             top.location = window.location
             top.location.replace(window.location.pathname)
             window.top.location = window.self.location
             setTimeout(function(){document.body.innerHTML=’’;},1);
             window.self.onload = function(evt){document.body.innerHTML=’’;}
             var url = window.location.href; top.location.replace(url)
            
  • https://redsiege.com/blog/2024/01/you-cant-see-me-protecting-your-phishing-infrastructure/
  • https://janbakker.tech/evilginx-resources-for-microsoft-365/
  • Evilginx + BITB - https://www.youtube.com/watch?v=luJjxpEwVHI&feature=youtu.be
  • Hook, Line and Sinker: Phishing Windows Hello for Business avec Evilginx : https://medium.com/@yudasm/bypassing-windows-hello-for-business-for-phishing-181f2271dc02
  • Phishing resistant - Phishing pour le jeton d'actualisation principal dans Microsoft Entra par Dirk Jan : https://youtu.be/tNh_sYkmurI?si=qcb917IB5zHU1fQk
  • X33fcon 2024 - https://youtu.be/Nh99d3YnpI4?si=Ltwus2PS0z97gf2R
  • Like Shooting Phish in a Barrel - Contourner les crawlers de liens : ****https://posts.specterops.io/like-shooting-phish-in-a-barrel-926c1905bb4b
  • Drink Like a Phish - Comment faire en sorte que vos sites de phishing se fondent dans le décor : https://posts.specterops.io/drink-like-a-phish-b9e91d0b5677
  • Feeding the Phishes : ****https://posts.specterops.io/feeding-the-phishes-276c3579bba7
  • https://posts.specterops.io/phish-out-of-water-aaeb677a5af3
  • https://youtu.be/6jYZQKDlKco?si=cpfd4tWQ4V8ZAZaI
  • https://posts.specterops.io/one-phish-two-phish-red-teams-spew-phish-1a2f02010ed7
  • Détection des outils de phishing Push Security : https://gist.github.com/rad9800/bb73de360fc07ac544f0bc9faac9082d
    • L'extension Chrome de Push Security détecte evilginx avec des règles assez fragiles
      • Règle 1 : Nom du cookie=XXXX-XXXX & value=64_hex_chars
      • Règle 2 : Chemin du script=/s/64_hex_chars.js avec content-length=0
      • Règle 3 : Les deux règles 1 et 2 présentes
      • La logique complète du blob JS est ici https://gist.github.com/rad9800/bb73de360fc07ac544f0bc9faac9082d
  • https://janbakker.tech/evilginx-loves-temporary-access-passes-too/
  • Modifier la réponse 404

    • Ajouter la fonction personnalisée ci-dessous dans le fichier controllers/phish.go

      root@kitploit:~
      func customNotFound(w http.ResponseWriter, r *http.Request) {
      	http.Error(w, "Try again!", http.StatusNotFound)
      }
      
    • Maintenant, remplacez toutes les instances de http.NotFound(w, r) par customNotFound(w, r)

  • Supprimer la réponse codée en dur de robots.txt et la modifier dans le fichier controllers/phish.go

    • Modifier le code correspondant dans le fichier phish.go comme ci-dessous.

      root@kitploit:~
      //Modified Response
      // RobotsHandler prevents search engines, etc. from indexing phishing materials
      func (ps *PhishingServer) RobotsHandler(w http.ResponseWriter, r *http.Request) {
      	fmt.Fprintln(w, "User-agent: *\nDisallow: /*/*\nDisallow: /.git/*")
      }
      
  • Modifier le paramètre GET "rid" dans les requêtes

    • Assurez-vous de modifier toutes les instances de "rid" en quelque chose d'autre.
    • Ceux-ci sont également présents dans le code source d'evilginx3.3, alors assurez-vous de les modifier également.
  • Pour des préventions avancées, vous pouvez également modifier le dossier statique et le renommer, ainsi que renommer les fichiers à l'intérieur pour éviter la détection basée sur le chemin. N'oubliez pas de modifier également le code source correspondant.

    • Comme le nom des images, exemple : pixel.png, modifiez-le en quelque chose d'autre.
  • Modifier les propriétés du certificat dans le fichier util/util.go

    root@kitploit:~
    	template := x509.Certificate{
    		SerialNumber: serialNumber,
    		Subject: pkix.Name{
    			//Organization: []string{"Gophish"},
    			Organization: []string{"Microsoft Corporation"},
    		},
    
  • Utiliser Nginx pour proxyfier le trafic afin d'éviter toute empreinte du serveur Golang

    • service nginx start

    • Vous devez modifier le config.json de gophish pour changer les ports http de 80 à 8080 et https de la valeur par défaut à 60002, comme indiqué ci-dessous

      root@kitploit:~
      {
      	"admin_server": {
      		"listen_url": "127.0.0.1:60002",
      		"use_tls": true,
      		"cert_path": "gophish_admin.crt",
      		"key_path": "gophish_admin.key",
      		"trusted_origins": []
      	},
      	"phish_server": {
      		"listen_url": "127.0.0.1:8080",
      		"use_tls": false,
      		"cert_path": "example.crt",
      		"key_path": "example.key"
      	},
      	"db_name": "sqlite3",
      	"db_path": "gophish.db",
      	"migrations_prefix": "db/db_",
      	"contact_address": "",
      	"logging": {
      		"filename": "",
      		"level": ""
      	}
      }
      
    • La configuration ci-dessous bloquera toutes les requêtes dont l'agent utilisateur contient « Bot » ou « bot »

      root@kitploit:~
      # /etc/nginx/nginx.conf
      
      events {
          # Define event processing parameters here
          worker_connections 1024; # Adjust according to your requirements
      }
      
      http {
      
          upstream backend {
              server localhost:8080;
          }
          # HTTP server
          server {
              listen 80 default_server;
              
      
              # Reject requests with "bot" or "Bot" in User-Agent
              if ($http_user_agent ~* (bot|Bot)) {
                  return 403;
              }
      
              location / {
                  proxy_pass http://backend;
                  proxy_set_header Host $host;
                  proxy_set_header X-Real-IP $remote_addr;
                  proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
                  proxy_set_header X-Forwarded-Proto $scheme;
              }
          }
      
          upstream backend_https {
              server localhost:60002;
          }
          # HTTPS server
          server {
              listen 60001 ssl default_server;
      
              ssl_certificate /root/Phishing/gophish-mod/gophish_admin.crt;
              ssl_certificate_key /root/Phishing/gophish-mod/gophish_admin.key;
      
              # Reject requests with "bot" or "Bot" in User-Agent
              if ($http_user_agent ~* (bot|Bot)) {
                  return 403;
              }
      
              location / {
                  proxy_pass https://backend_https;
                  proxy_set_header Host $host;
                  proxy_set_header X-Real-IP $remote_addr;
                  proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
                  proxy_set_header X-Forwarded-Proto $scheme;
              }
          }
      }
      
      
    • Pour autoriser uniquement un agent utilisateur spécifique, utilisez la configuration ci-dessous. Cela bloquera toutes les requêtes et n'autorisera que celles dont l'agent utilisateur est « iamdevil ».

      root@kitploit:~
      # /etc/nginx/nginx.conf
      
      events {
          # Define event processing parameters here
          worker_connections 1024; # Adjust according to your requirements
      }
      
      http {
      
          upstream backend {
              server localhost:8080;
          }
      
          # HTTP server
          server {
              listen 80 default_server;
      
              # Reject requests with user agent other than "iamdevil"
              if ($http_user_agent != "iamdevil") {
                  return 403;
              }
      
              location / {
                  proxy_pass http://backend;
                  proxy_set_header Host $host;
                  proxy_set_header X-Real-IP $remote_addr;
                  proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
                  proxy_set_header X-Forwarded-Proto $scheme;
              }
          }
      
          upstream backend_https {
              server localhost:60002;
          }
      
          # HTTPS server
          server {
              listen 60001 ssl default_server;
      
              ssl_certificate /root/Phishing/gophish-mod/gophish_admin.crt;
              ssl_certificate_key /root/Phishing/gophish-mod/gophish_admin.key;
      
              # Reject requests with user agent other than "iamdevil"
              if ($http_user_agent != "iamdevil") {
                  return 403;
              }
      
              location / {
                  proxy_pass https://backend_https;
                  proxy_set_header Host $host;
                  proxy_set_header X-Real-IP $remote_addr;
                  proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
                  proxy_set_header X-Forwarded-Proto $scheme;
              }
          }
      }
      
  • Modifier la signature du pixel de suivi GoPhish pour éviter la détection basée sur un pixel de suivi signé.

  • Modifier le modèle de séquence des en-têtes d'e-mail de gophish. Il peut être utilisé pour détecter gophish (d'après la communauté BreakDev Red).

  • Configurer PostFix devant gophish pour supprimer les IOCs et autres détections et la spammitude des e-mails, et également supprimer et corriger les en-têtes.

  • Blogs/Talks de recherche GoPhish :

    • https://edermi.github.io/post/2021/modding_gophish/
    • https://www.sprocketsecurity.com/resources/never-had-a-bad-day-phishing-how-to-set-up-gophish-to-evade-security-controls
    • https://cyberwarfare.live/wp-content/uploads/2023/08/OPSEC-on-the-High-Seas_-A-Gophish-Adventure.pdf
    • https://www.sprocketsecurity.com/resources/never-had-a-bad-day-phishing-how-to-set-up-gophish-to-evade-security-controls
    • https://github.com/puzzlepeaches/sneaky_gophish
    • https://cybercx.co.nz/blog/identifying-gophish-servers/
    • https://github.com/gophish/gophish/issues/1553#issuecomment-523969887
  • Alternatives à GoPhish :

    • SniperPhish : https://github.com/GemGeorge/SniperPhish
    • Mailcow : https://github.com/mailcow/mailcow-dockerized
  • https://adepts.of0x.cc/novnc-phishing/
    • EvilnoVNC : https://github.com/JoelGMSec/EvilnoVNC
    • MultiEvilnoVNC : https://blog.wanetty.com/blog/tools/multievilnovnc
    • https://fhlipzero.io/blogs/6_noVNC/noVNC.html
    • Delusion (Kit basé sur NoVNC) : https://cloud.google.com/blog/topics/threat-intelligence/session-stealing-browser-in-the-middle
    • Détection de NoVNC : https://gist.github.com/rad9800/bb73de360fc07ac544f0bc9faac9082d
  • noVNC et Docker : https://powerseb.github.io/posts/Another-phishing-tool/
    • https://github.com/powerseb/NoPhish
    • https://fhlipzero.io/blogs/6_noVNC/noVNC.html
    • https://github.com/Macmod/YesPhish/tree/patchright-chrome
  • EvilQR - Phishing par QR
    • Générer QR : https://github.com/Flangvik/QRucible
    • https://badoption.eu/blog/2024/01/08/mobilephish.html
    • QR2Ascii : https://github.com/Jojodicus/qr2eascii
    • https://github.com/kgretzky/evilqr , https://breakdev.org/evilqr-phishing/
    • https://github.com/swagkarna/EvilJack
    • https://techcommunity.microsoft.com/t5/microsoft-security-experts-blog/hunting-for-qr-code-aitm-phishing-and-user-compromise/bc-p/4054850
  • NoPhish (docker et noVNC) : https://github.com/powerseb/NoPhish et https://badoption.eu/blog/2023/07/12/entra_phish.html
  • EvilGoPhish : https://github.com/fin3ss3g0d/evilgophish
  • Smishing : https://blog.shared-video.mov/systematic-destruction-hacking-the-scammers-pt.-2
  • Phishing avec CloudFlare Workers
    • TryCloudflare : https://developers.cloudflare.com/cloudflare-one/connections/connect-networks/do-more-with-tunnels/trycloudflare/
    • https://github.com/zolderio/AITMWorker
    • https://gist.github.com/RedTeamOperations/33f245a777c9b322b0466b59d6687f15
    • https://cyberwarfare.live/wp-content/uploads/2023/08/Certified-Red-Team-CredOps-Infiltrator-CRT-COI-1.pdf
  • Phishing avec Cloudflare Public Buckets : https://developers.cloudflare.com/r2/buckets/public-buckets/
    • https://medium.com/trac-labs/aitm-phishing-hold-the-gabagool-analyzing-the-gabagool-phishing-kit-531f5bbaf0e4
  • Redirection ouverte Google pour le phishing
    • https://untrustednetwork.net/en/2024/02/26/google-open-redirect/
    • Redirection ouverte (ne fonctionne pas) : https://googleweblight.com/i?u=m4lici0u5.com
    • Redirection ouverte : https://www.google.com/url?q=https://m4lici0u5.com
    • Redirection ouverte : https://business.google.com/website_shared/launch_bw.html?f=https://m4lici0u5.com
    • Plus d'informations sur : https://lots-project.com/
  • https://blog.delivr.to/delivr-tos-top-10-payloads-dec-24-pastejacking-image-less-qr-codes-and-concatenated-zip-a32e668106dd#878d
  • Phishing contournant les contrôles de protection des e-mails avec Azure Information Protection
    • https://youtu.be/tHNi5BzScVo?si=H2czog19AmTp_O26
    • https://youtu.be/EYUp_MNtJIk?si=sg_9RQggDvqOSLNL
    • https://youtu.be/KhdzIPPW4W0?si=E4CmWx0iO8EaR6JF
  • https://nicolasuter.medium.com/aitm-phishing-with-azure-functions-a1530b52df05
  • https://pushsecurity.com/blog/a-new-class-of-phishing-verification-phishing-and-cross-idp-impersonation/
  • https://blog.delivr.to/delivr-tos-top-10-payloads-dec-24-pastejacking-image-less-qr-codes-and-concatenated-zip-a32e668106dd#878d
  • https://trustedsec.com/blog/oops-i-udld-it-again
  • Phishing d'identifiants par abus de Docusign : https://sublime.security/blog/living-off-the-land-credential-phishing-via-docusign-abuse/
  • Phishing d'identifiants caché avec pièces jointes EML : https://sublime.security/blog/hidden-credential-phishing-within-eml-attachments/
  • https://sublime.security/blog/talking-year-end-credential-phishing-scams-over-turkey/
  • Utilisation de Microsoft Customer Voice pour le phishing : https://cofense.com/blog/microsoft-customer-voice-urls-used-in-latest-phishing-campaign
  • https://www.youtube.com/live/tOzURCc-qUc?si=DMkLwXHVQomRMEJD
  • DoubleClickJacking : https://www.paulosyibelo.com/2024/12/doubleclickjacking-what.html
    • https://safetyscience.info/labs/doubleclickjacking/
  • Comparaison de diverses techniques : https://blog.quarkslab.com/technical-dive-into-modern-phishing.html
  • https://cloud.google.com/blog/topics/threat-intelligence/session-stealing-browser-in-the-middle
  • Abus des webhooks entrants Microsoft Teams pour le phishing : https://www.blackhillsinfosec.com/wishing-webhook-phishing-in-teams/
    • https://www.youtube.com/live/kMMZrd9intI?si=rd_EKWmXeKbbGAEI
  • Rogue RDP ou RDP (.rdp) pour le phishing : https://github.com/GoSecure/pyrdp
    • https://cloud.google.com/blog/topics/threat-intelligence/windows-rogue-remote-desktop-protocol
    • https://www.blackhillsinfosec.com/rogue-rdp-revisiting-initial-access-methods/
  • https://easydmarc.com/blog/google-spoofed-via-dkim-replay-attack-a-technical-breakdown/
  • SVG pour le phishing : https://www.trustwave.com/en-us/resources/blogs/spiderlabs-blog/pixel-perfect-trap-the-surge-of-svg-borne-phishing-attacks/
  • Utilisation de ClickOnce avec le phishing pour l'accès initial : https://www.netspi.com/blog/technical-blog/adversary-simulation/all-you-need-is-one-a-clickonce-love-story/
  • https://denniskniep.github.io/posts/09-device-code-phishing/
  • https://badoption.eu/blog/2025/04/25/github.html
  • https://atticsecurity.com/blog/aitm-for-whfb-persistence/
  • [À voir absolument] Evilworker : https://github.com/Ahaz1701/EvilWorker
    • https://medium.com/@ahaz1701/evilworker-da94ae171249